CVE-2026-33990Patch(docker / model_runner)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch docker model_runner systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains an SSRF vulnerability in its OCI registry token exchange flow. When pulling a model, Model Runner follows the realm URL from the registry's WWW-Authenticate header without validating the scheme, hostname, or IP range. A malicious OCI registry can set the realm to an internal URL (e.g., http://127.0.0.1:3000/), causing Model Runner running on the host to make arbitrary GET requests to internal services and reflect the full response body back to the caller. Additionally, the token exchange mechanism can relay data from internal services back to the attacker-controlled registry via the Authorization: Bearer header. This issue has been patched in version 1.1.25. For Docker Desktop users, enabling Enhanced Container Isolation (ECI) blocks container access to Model Runner, preventing exploitation. However, if the Docker Model Runner is exposed to localhost over TCP in specific configurations, the vulnerability is still exploitable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • model_runner

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
model_runner

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-30: 1Mentions · 2026-09-17: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-03-30: 1Technical Details · 2026-09-17: 103-3009-17
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Threat Landscape@LandscapeThreat
    Patch

    Docker disclosed two Docker Sandboxes vulnerabilities that can allow malicious guest environments to escape workspace isolation and access host resources. CVE-2026-77179, affecting macOS versions before 0.42.0, enables symlink-race redirection of filesystem operations, potentially permitting arbitrary file read/write and host code execution. CVE-2026-79994, affecting versions before 0.42.0, can redirect guest-to-host Unix socket connections to unauthorized AF_UNIX sockets, enabling data disclosure or access to host-side functions. Docker recommends upgrading to 0.42.0 or later, using clone mode, removing writable host mounts, and minimizing sensitive data in shared paths. VULNERABILITY CVE-2026-17106 CVE-2026-2664 CVE-2026-28400 CVE-2026-33990 CVE-2026-5817 CVE-2026-5843 CVE-2026-77179 CVE-2026-79994

    Post summary

    The text discloses two Docker Sandbox vulnerabilities (CVE-2026-77179 and CVE-2026-79994) affecting versions before 0.42.0, detailing their technical impact and recommending an upgrade to 0.42.0 or later along with specific workarounds.

    2004173
    98 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    Addressed CVE-2026-33990, SSRF in Docker Model Runner OCI Registry Client Security announcements | Docker Docs Docker Desktop 4.67.0 security update: CVE-2026-33990 https://docs.docker.com/security/security-announcements/#docker-desktop-4670-security-update-cve-2026-33990

    Post summary

    Docker issued a security update (Docker Desktop 4.67.0) that addresses the SSRF vulnerability CVE-2026-33990 in the Model Runner OCI Registry Client, with no PoC or active exploitation reported.

    00000329
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdockermodel_runner-docker-

Explore more